Commit: patch 9.2.0839: [security]: arbitrary code execution via keyword lookup

Christian Brabandt <[email protected]>
Newsgroups gmane.editors.vim.devel
Message-ID <[email protected]>
patch 9.2.0839: [security]: arbitrary code execution via keyword lookup

Commit: https://github.com/vim/vim/commit/c5a82fe013e73c98004ad7cd4f906b1ad1ed610e
Author: Yasuhiro Matsumoto <[email protected]>
Date:   Thu Jul 23 19:13:15 2026 +0000

    patch 9.2.0839: [security]: arbitrary code execution via keyword lookup
    
    Problem:  [security]: arbitrary code execution via keyword lookup in
              sh.vim, zsh.vim and ps1.vim filetype plugin
              (manus-use)
    Solution: For powershell, quote the commands using single quotes, for
              sh/zsh pass the argument as a separate list item to term_start()/system()
              (Yasuhiro Matsumoto).
    
    Github Security Advisory:
    https://github.com/vim/vim/security/advisories/GHSA-r5v6-q6j8-8qw2
    
    Signed-off-by: Yasuhiro Matsumoto <[email protected]>
    Signed-off-by: Christian Brabandt <[email protected]>

diff --git a/runtime/ftplugin/ps1.vim b/runtime/ftplugin/ps1.vim
index f1fe78df4..9ff764a28 100644
--- a/runtime/ftplugin/ps1.vim
+++ b/runtime/ftplugin/ps1.vim
@@ -6,6 +6,7 @@
 "              2024 May 23 by Riley Bruins <[email protected]> ('commentstring')
 "              2024 Sep 19 by Konfekt (simplify keywordprg #15696)
 "              2025 Jul 22 by phanium (use :hor term #17822)
+"              2026 Jul 10 by Vim Project (quote K argument, prevent command injection)
 
 " Only do this when not done yet for this buffer
 if exists("b:did_ftplugin") | finish | endif
@@ -52,9 +53,9 @@ endif
 
 if exists('s:pwsh_cmd')
   if exists(':terminal') == 2
-    command! -buffer -nargs=1 GetHelp silent exe 'hor term ' . s:pwsh_cmd . ' -NoLogo -NoProfile -NonInteractive -ExecutionPolicy RemoteSigned -Command Get-Help -Full "<args>"' . (executable('less') ? ' | less' : '')
+    command! -buffer -nargs=1 GetHelp call term_start([s:pwsh_cmd, '-NoLogo', '-NoProfile', '-NonInteractive', '-ExecutionPolicy', 'RemoteSigned', '-Command', "Get-Help -Full '" . substitute(<q-args>, "'", "''", 'g') . "'" . (executable('less') ? ' | less' : '')])
   else
-    command! -buffer -nargs=1 GetHelp echo system(s:pwsh_cmd . ' -NoLogo -NoProfile -NonInteractive -ExecutionPolicy RemoteSigned -Command Get-Help -Full <args>')
+    command! -buffer -nargs=1 GetHelp echo system([s:pwsh_cmd, '-NoLogo', '-NoProfile', '-NonInteractive', '-ExecutionPolicy', 'RemoteSigned', '-Command', "Get-Help -Full '" . substitute(<q-args>, "'", "''", 'g') . "'"])
   endif
   setlocal keywordprg=:GetHelp
   let b:undo_ftplugin ..= " | setl kp< | sil! delc -buffer GetHelp"
diff --git a/runtime/ftplugin/sh.vim b/runtime/ftplugin/sh.vim
index 18cd219cd..45e6f44fc 100644
--- a/runtime/ftplugin/sh.vim
+++ b/runtime/ftplugin/sh.vim
@@ -8,6 +8,7 @@
 "			2024 Dec 29 by Vim Project (improve setting shellcheck compiler)
 "			2025 Mar 09 by Vim Project (set b:match_skip)
 "			2025 Jul 22 by phanium (use :hor term #17822)
+"			2026 Jul 10 by Vim Project (pass K argument as a list, prevent shell injection)
 
 if exists("b:did_ftplugin")
   finish
@@ -54,9 +55,9 @@ let s:is_kornshell = get(b:, "is_kornshell", get(g:, "is_kornshell", 0))
 
 if s:is_bash
   if exists(':terminal') == 2
-    command! -buffer -nargs=1 ShKeywordPrg silent exe ':hor term bash -c "help "<args>" 2>/dev/null || man "<args>""'
+    command! -buffer -nargs=1 ShKeywordPrg call term_start(['bash', '-c', 'help "$1" 2>/dev/null || man "$1"', '--', <q-args>])
   else
-    command! -buffer -nargs=1 ShKeywordPrg echo system('bash -c "help <args>" 2>/dev/null || MANPAGER= man "<args>"')
+    command! -buffer -nargs=1 ShKeywordPrg echo system(['bash', '-c', 'help "$1" 2>/dev/null || MANPAGER= man "$1"', '--', <q-args>])
   endif
   setlocal keywordprg=:ShKeywordPrg
   let b:undo_ftplugin ..= " | setl kp< | sil! delc -buffer ShKeywordPrg"
diff --git a/runtime/ftplugin/zsh.vim b/runtime/ftplugin/zsh.vim
index 850bef055..816358593 100644
--- a/runtime/ftplugin/zsh.vim
+++ b/runtime/ftplugin/zsh.vim
@@ -2,7 +2,7 @@
 " Language:             Zsh shell script
 " Maintainer:           Christian Brabandt <[email protected]>
 " Previous Maintainer:  Nikolai Weibull <[email protected]>
-" Latest Revision:      2025 Jul 23
+" Latest Revision:      2026 Jul 23
 " License:              Vim (see :h license)
 " Repository:           https://github.com/chrisbra/vim-zsh
 
@@ -25,9 +25,9 @@ endif
 
 if executable('zsh') && &shell !~# '/\%(nologin\|false\)$'
   if exists(':terminal') == 2
-    command! -buffer -nargs=1 ZshKeywordPrg silent exe ':hor :term zsh -c "autoload -Uz run-help; run-help <args>"'
-  else
-    command! -buffer -nargs=1 ZshKeywordPrg echo system('MANPAGER= zsh -c "autoload -Uz run-help; run-help <args> 2>/dev/null"')
+    command! -buffer -nargs=1 ZshKeywordPrg call term_start(['zsh', '-c', 'autoload -Uz run-help; run-help "$1"', '--', <q-args>])
+  elseif has("patch-9.2.0250")
+    command! -buffer -nargs=1 ZshKeywordPrg echo system(['zsh', '-c', 'autoload -Uz run-help; MANPAGER= run-help "$1" 2>/dev/null', '--', <q-args>])
   endif
   setlocal keywordprg=:ZshKeywordPrg
   let b:undo_ftplugin .= '| setl keywordprg< | sil! delc -buffer ZshKeywordPrg'
diff --git a/src/version.c b/src/version.c
index 07772b03f..9d3c95b00 100644
--- a/src/version.c
+++ b/src/version.c
@@ -758,6 +758,8 @@ static char *(features[]) =
 
 static int included_patches[] =
 {   /* Add new patch number below this line */
+/**/
+    839,
 /**/
     838,
 /**/

-- 
-- 
You received this message from the "vim_dev" maillist.
Do not top-post! Type your reply below the text you are replying to.
For more information, visit http://www.vim.org/maillist.php

--- 
You received this message because you are subscribed to the Google Groups "vim_dev" group.
To unsubscribe from this group and stop receiving emails from it, send an email to [email protected].
To view this discussion visit https://groups.google.com/d/msgid/vim_dev/E1wmzLt-00ANFn-BP%40256bit.org.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.